ÐÅÏ¢Äþ¾²Öܱ¨-2019ÄêµÚ38ÖÜ
Ðû²¼Ê±¼ä 2019-09-30±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö
2019Äê9ÔÂ23ÈÕÖÁ29ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´43¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇRIOT MQTT-SN CVE-2019-16754¿ÕÖ¸Õë¼ä½ÓÒýÓ鶴; vBulletin widgetConfig[code]Ô¶³Ì´úÂëÖ´ÐЩ¶´£»Adobe ColdFusionÈÎÒâ´úÂëÖ´ÐЩ¶´£»Microsoft Internet ExplorerÄڴ湤¾ß´¦ÖÃÔ¶³Ì´úÂëÖ´ÐЩ¶´£»phpstudyºóÃÅÖ²È멶´¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇTescoÍ£³µÓ¦ÓôæÔÚ©¶´µ¼ÖÂÊýǧÍò³µÅÆͼÏñй¶£»Î¢Èí½ô¼±ÐÞ¸´IEÖеÄRCE 0day¼°DefenderÖеÄDoS©¶´£»¾Ýͳ¼Æ2019ÄêÃÀ¹úÒÑÓжà´ï500ËùѧУÔâÀÕË÷Èí¼þ¹¥»÷£»iOS 13ºÍiPadOS©¶´¿Éµ¼ÖµÚÈý·½¼üÅÌ»ñÈ¡ÍêÈ«·ÃÎÊȨÏÞ£»iOS©¶´Checkm8¿Éµ¼ÖÂiPhone4µ½XÓÀ¾ÃÔ½Óü¡£
ÖØÒªÄþ¾²Â©¶´Áбí
RIOT MQTT-SNʵÏÖ´æÔÚ¿ÕÖ¸ÕëÒýÓ鶴£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉʹϵͳÍ߽⡣
https://github.com/RIOT-OS/RIOT/pull/12293
2. vBulletin widgetConfig[code]Ô¶³Ì´úÂëÖ´ÐЩ¶´
vBulletin ajax/render/widget_php routestring´¦ÖÃwidgetConfig[code]´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâÃüÁî¡£
https://seclists.org/fulldisclosure/2019/Sep/31
3. Adobe ColdFusionÈÎÒâ´úÂëÖ´ÐЩ¶´
Adobe ColdFusionij×é¼þ´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿É×¢ÈëÈÎÒâÃüÁî²¢Ö´ÐС£
https://helpx.adobe.com/security/products/coldfusion/apsb19-47.html
4. Microsoft Internet ExplorerÄڴ湤¾ß´¦ÖÃÔ¶³Ì´úÂëÖ´ÐЩ¶´
Microsoft Internet Explorer´¦ÖÃÄڴ湤¾ß´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄWEBÇëÇó£¬ÓÕʹÓû§½âÎö£¬¿ÉʹӦÓ÷¨Ê½±ÀÀ£»òÖ´ÐÐÈÎÒâ´úÂë¡£
https://support.microsoft.com/zh-cn/help/4522007/cumulative-security-update-for-internet-explorer
5. phpstudyºóÃÅÖ²È멶´
phpstudy±»×¢ÈëºóÃÅ£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ØÖÆÄ¿±êÓ¦ÓÃϵͳ¡£
https://www.xp.cn/
ÖØÒªÄþ¾²Ê¼þ×ÛÊö
ÔÎÄÁ´½Ó£º
https://www.theregister.co.uk/2019/09/20/tesco_parking_app_10s_millions_anpr_photos_exposed/
2¡¢Î¢Èí½ô¼±ÐÞ¸´IEÖеÄRCE 0day¼°DefenderÖеÄDoS©¶´
΢ÈíÐû²¼½ô¼±Äþ¾²¸üУ¬ÐÞ¸´IEÖеÄRCE 0day¼°Windows DefenderÖеÄDoS©¶´¡£ÆäÖÐIE 0dayΪ¹È¸èÑо¿ÈËÔ±Cl¨¦mentLecigne·¢ÏֵĽű¾ÒýÇæÄÚ´æËð»µÂ©¶´£¨CVE-2019-1367£©£¬¹¥»÷Õß¿ÉÀûÓø鶴ÔÚµ±Ç°Óû§µÄÉÏÏÂÎÄÖÐÖ´ÐÐÈÎÒâ´úÂë¡£¸Ã©¶´¿ÉÒÔͨ¹ý½«Ä¿±êÓû§Öض¨ÏòÖÁ¶ñÒâÍøÕ¾À´ÀûÓã¬ÊÜÓ°ÏìµÄ°æ±¾°üÂÞIE9¡¢10ºÍ11¡£ÁíÒ»¸ö©¶´ÊÇWindows DefenderÖеľܾø·þÎñ©¶´£¨CVE-2019-1255£©£¬¸Ã©¶´ÓëDefender´¦ÖÃÎļþµÄ·½Ê½Óйأ¬¹¥»÷Õß¿ÉÀûÓø鶴×èÖ¹ºÏ·¨ÕË»§Ö´ÐкϷ¨µÄϵͳÎļþ¡£ÊÜÓ°ÏìµÄDefender°æ±¾Îª1.1.16300.1£¬²¢ÒÑÔÚ1.1.16400.2ÖÐÐÞ¸´¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/microsoft-releases-out-of-band-security-update-to-fix-ie-zero-day-defender-bug/
3¡¢¾Ýͳ¼Æ2019ÄêÃÀ¹úÒÑÓжà´ï500ËùѧУÔâÀÕË÷Èí¼þ¹¥»÷
ƾ¾ÝÔÆÄþ¾²¹«Ë¾ArmorµÄµ÷ÑУ¬ÃÀ¹úÒÑÓÐ49¸öѧÇøµÄ½ÌÓý»ú¹¹Ôâµ½ÀÕË÷Èí¼þ¹¥»÷£¬Ê¹µÃ½ÌÓýÐÐÒµ³ÉΪ½ö´ÎÓڵط½Õþ¸®µÄµÚ¶þ´óÒ×Êܹ¥»÷Ä¿±ê¡£¸Ã¹«Ë¾·ÖÎöÁË×Ô2019Äê1ÔÂÒÔÀ´¹ûÈ»±¨µÀµÄ¹¥»÷£¬·¢ÏÖÔÚ2019ÄêÇ°9¸öÔÂÒÑÓжà´ï500ËùK-12ѧУÔâµ½¹¥»÷£¬¶øÈ¥ÄêÖ»ÓÐ11ËùѧУ¡£½öÔÚ9ÔÂÖÐÑ®µÄÒ»Öܶàʱ¼äÀï¾ÍÓÐ9¸öÐÂѧÇøºÍ1Ëù´óѧÊܵ½¹¥»÷£¬²¨¼°Ô¼100ËùK-12ѧУ¡£¿µÄùµÒ¸ñÖݵÄѧÇøÊܵ½µÄÍþв×îΪÑÏÖØ£¬¸ÃÖݹ²ÔâÓöÁË7´Î¹¥»÷£¬º¸Ç104ËùѧУ¡£
ÔÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/hundreds-of-us-schools-hit-by/4¡¢iOS 13ºÍiPadOS©¶´¿Éµ¼ÖµÚÈý·½¼üÅÌ»ñÈ¡ÍêÈ«·ÃÎÊȨÏÞ
ÔÎÄÁ´½Ó£º
https://threatpost.com/bug-granting-full-access-keyboards/148638/5¡¢iOS©¶´Checkm8¿Éµ¼ÖÂiPhone4µ½XÓÀ¾ÃÔ½Óü
Äþ¾²Ñо¿Ô±axi0mXÅû¶iOSÖеÄÄþ¾²Â©¶´checkm8£¬¸Ã©¶´¿ÉÒÔʹiPhone4S£¨A5оƬ£©µ½iPhone8¡¢iPhoneX£¨A11оƬ£©µÄËùÓÐÆ»¹ûÊÖ»ú¼°Í¬¿îAϵÁд¦ÖÃÆ÷µÄiPad¡¢iPod touchµÈiOSÉ豸ÓÀ¾ÃÔ½Óü¡£Ã»ÓÐÌáµ½×îеÄA12ºÍA13ÊÇ·ñÊܵ½Ó°Ïì¡£¸Ã¹¥»÷ÀûÓÃÁËbootrom©¶´£¬¼´´æ´¢ÁËiPhoneÆô¶¯Ö¸ÁîµÄÖ»¶Á´æ´¢Æ÷£¨ROM£©Â©¶´£¬ÓÉÓڸò¿ÃÅÄÚ´æÊÇÖ»¶ÁµÄ£¬Òò´ËÎÞ·¨Í¨¹ýÄþ¾²¸üÐÂÀ´ÐÞ¸´Â©¶´¡£Ñо¿ÈËÔ±ÔÚGithubÉÏÐû²¼ÁËÏà¹Ø©¶´ÀûÓ㬵«ÉÐÎÞ¹ûÈ»¿ÉÓõÄÔ½Óü·¨Ê½¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/ios-exploit-checkm8-could-allow-permanent-iphone-jailbreaks/148762/